Skip to main content
PanelReady

Legal

Privacy Policy

What IDE Host collects when you use PanelReady, why, how long we keep it, who we share it with, and how to delete it — in English a human can read.

Last updated · 25 May 2026

Privacy Policy

This Privacy Policy explains how IDE Host (OPC) Pvt. Ltd.("we", "us"), the company that operates PanelReady, handles personal data when you use PanelReady ("the Service").

We are the data controller. We follow the principles of the EU/UK GDPR, California's CCPA/CPRA, and India's Digital Personal Data Protection Act (DPDP Act 2023). If a stronger local law applies to you, it controls.

Short version. PanelReady is an interview preparation platform — not a coaching service. We collect the basic data we need to deliver the product, score your interviews against published rubrics, send you the email you asked for, bill you accurately, and improve the user experience over time. We do not sell your personal data, we do not run advertising on the Service, and we do not use your interview content to train third-party foundation models.

1. What we collect

You give us directly

  • Account data — name, email, password hash (if you use email + password), social-provider id (if you sign in with Google, Apple, or LinkedIn).
  • Profile data — target track, target level, target companies, country, locale, phone number (if you enter one).
  • Interview content — your spoken answers during voice interviews, the transcripts derived from them, rubric scores, and feedback we generate.
  • Resume + supporting docs — resume files you upload, social profile URLs (LinkedIn, GitHub, personal site), and any job descriptions you paste at interview start.
  • Billing data — handled by our payment processor. We see the last 4 digits of your card and the billing country; we never see your full card number.

We collect automatically (basic UX telemetry)

We track the minimum amount of behavioural data we need to understand how the product is used and to make it better. This is explicit and bounded — we collect for product improvement, not for ad targeting.

  • Usage data — pages and routes you visit, features you click, the order you step through onboarding in, interview start/end timestamps, the buttons you tap inside the live room, error events. We use it to spot broken flows, prioritize what to build next, and tune the interview agent.
  • Device + session data — browser, browser version, operating system, screen size, approximate region (derived from IP, not stored as the raw IP after the request), session length. Used for compatibility testing and abuse detection.
  • Performance data — Core Web Vitals (LCP, CLS, INP), JS errors, API latency. Helps us catch regressions before they hit everyone.
  • Cookies + local storage — strictly the ones needed to keep you signed in, remember your theme preference, persist your in-progress interview, and attribute the analytics events above. We do not run third- party advertising cookies, retargeting pixels, or cross-site identifiers.

2. Why we use it

  • Deliver the Service — running interviews, grading them against the rubric for your level, showing your history.
  • Improve the Service — aggregate, anonymized signals shape future rubric and prompt updates. Your raw content is not used to train foundation models.
  • Communicate — transactional emails (sign-in links, billing receipts), and product updates only if you opted in.
  • Process payments — sharing the minimum necessary metadata with our payment processor to bill you accurately.
  • Identify usage trends — understanding how the product is used so we can improve it (fix broken flows, tune the interview agent, prioritize what to build next).
  • Protect the Service — fraud monitoring, rate-limiting, abuse detection, and account-security checks.
  • Comply with the law — response to lawful requests and the limited record-keeping that tax authorities require.

3. Legal bases (EU/UK GDPR)

The General Data Protection Regulation (GDPR) and UK-GDPR require us to state the legal bases we rely on to process your personal information. We rely on the following:

  • Performance of a contract — to deliver the Service to you (run interviews, score answers, show your history, process the subscription you signed up for).
  • Legitimate interests — to keep the product safe and reliable, prevent fraud, analyze how the Service is used so we can improve user experience, and send service-related communications. We balance these against your fundamental rights and freedoms.
  • Consent — for non-essential cookies, marketing emails, and any audio-recording you allow before a live interview. You can withdraw consent at any time.
  • Legal obligation — to comply with tax, accounting, anti-fraud, and law-enforcement requirements.
  • Vital interests— in the rare case processing is necessary to protect a person's vital interests.

India's Digital Personal Data Protection Act (DPDP Act 2023) treats us as the Data Fiduciary for PanelReady users in India; the same purposes apply under the DPDP framework.

4. Audio recordings

Live interviews are recorded so the scoring pass has the actual audio to grade against. We ask for consent before the first recording. Each recording carries a retention expiry — by default 30 days after the scored feedback unlocks. After expiry, the audio file is deleted from our object storage; the transcript and score remain so your history stays useful.

You can delete a recording (and its transcript and score) at any time from the interview detail screen. Deletion is immediate from the user-facing surface and propagates to backups within 30 days.

5. Who we share with

We use third-party APIs and hosting services strictly to run the Service. We share only the minimum personal data required for each provider to perform its function on our behalf. Each provider is bound by contract to process your data only as we instruct, to keep it confidential, and to hold it to a security standard at least as strong as ours. The categories of providers we rely on are:

  • Cloud infrastructure — application hosting, database, object storage for files and recordings.
  • Real-time audio transport — to carry your voice between you and the interview agent during a live interview.
  • Speech-to-text and text-to-speech — to transcribe what you say and to give the interviewer a voice.
  • Language-model providers — to power the adaptive interviewer and the scoring rubric pass. Contractually, none of these providers may use your interview content to train their models.
  • Payment processing — to charge your subscription securely. Card data lives with the payment provider, not with us.
  • Transactional email — to send sign-in links and billing receipts.
  • Authentication — to keep your session signed in and your password hashed.
  • Product analytics and error monitoring — to understand how the product is used so we can improve it, and to detect bugs. IP addresses are anonymized where the provider supports it.

We do not sell personal data. We do not share it with advertisers. We do not enrich your profile from external data brokers. We will publish a more detailed processor list on request — email hello@getpanelready.com.

6. Where it lives

Database and storage live in the regions configured for your account or your program's cohort. For individual accounts the default region is US-East; Cohort and Institution clients can request EU or India residency at signing.

7. How long we keep it

  • Account data — for as long as your account exists. Deleting your account purges it.
  • Interview audio — 30 days after scoring, then auto-deleted from storage.
  • Transcripts + scores — for as long as your account exists. Deleted on account deletion.
  • Billing records — retained as required by tax law in your jurisdiction (typically 7 years).
  • Logs and analytics — 90 days, then aggregated and anonymized.

8. Your rights

Depending on where you live, you have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent for anything we relied on consent for. Most of these are self-serve from the settings screen — Export and Delete both live there. For anything you can't self-serve, email hello@getpanelready.com (subject: Privacy).

For DPDP-covered (India) users, we act as Data Fiduciary; you may nominate a representative or ask us to correct, complete, or erase your data. For GDPR/UK-GDPR users you may also lodge a complaint with your supervisory authority — but please reach us first; we typically resolve concerns inside one business day. CCPA/CPRA users have an explicit right to opt out of any "sale" or "sharing" of personal information; PanelReady does not sell or share personal data in the sense those terms are defined, so there is nothing additional to opt out of.

EU/UK users can also lodge a complaint with their supervisory authority. We'd rather you talk to us first — we typically resolve concerns inside one business day.

9. Children

PanelReady is not directed at, or marketed to, children under 18 years of age. We do not knowingly solicit data from or market to children under 18. By using the Service, you represent that you are at least 18 years old or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Service. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at hello@getpanelready.com. Cohort plans that include a younger demographic must obtain parental consent independently.

10. Security

Data is encrypted in transit (TLS 1.2+) and at rest in our storage and database providers. Production access requires SSO and hardware-key 2FA. We run incident response drills and post material breach notices to our terms-listed contact addresses within the legally required window.

11. Changes to this policy

Material updates are announced by email at least 14 days before they take effect. The "Last updated" stamp at the top of this page reflects the most recent non-material change.

12. Contact

Data controller: IDE Host (OPC) Pvt. Ltd.. Privacy inquiries go to hello@getpanelready.com. General product support is hello@getpanelready.com. We respond inside one business day.